identity varification method to a user’s account
Users can add their own identity confirmation methods for which they receive email notifications. The added method is not blocked
What are some considerations when deactivating users in SF?
A user that’s assigned as the sole recipient of workflow email alert cannot be deactivated
His records can be transferred to another user
The deactivated user will not be deleted from the system but will no longer be able to log in to SF
In what situations would you choose to freeze the user instead of deactivating them
User is the sole recipient of workflow email alert
If the user is a default owner of Leads or Cases
If the user is part of custom hierarchy fields
Freezing a user does not release the license for use by another user
What is My Domain?
What should an admin do before deploying a new My Domain?
The My Domain feature allows the use of a subdomain for a SF org to better manage login and authentication.
The company name can be included in the URL
subdomain must be tested for login problems by using thee new subdomain name to log in.
tabs and links within the SF org also need to be checked
application URLs and hard-coded references need to be updated before deployment
to avoid confusion, the upcoming change should be announced much earlier than the date of deployment
Single Sign On
What is true in the situation, when users start reporting that they are unable to reset their passwords?
SF password policies do not apply for SSO users
SSO users cannot reset their passwords within SF
Record level security
roles
sharing rules
Roles are used to create a sharing hierarchy among the users
Sharing rules can never be stricter than the organization-wide sharing derfaults
IP ranges, how can they be set?
Login IP Ranges - Profile level
Trusted IP Ranges - Org level
IP ranges can be set both Profile-level and Organization-wide, using Login IP ranges and Trusted IP Ranges, respectively.
However, only the Login IP Ranges setting is entirely restrictive.When the access denied, they see the same message, as if the username or password was wrong.
Trusted IP Ranges: Users can log in without receiving a login challenge for verification. If a user tries to log in outside the trusted IP Range, they receive an activation code
What a Delegated Administrator is allowed to go?
reset passwords for users in specific roles
create users
assign specific permission sets
manage custom objects
What options does SF Admin have regarding setting the page displayed after a user logs out of SF?
A Display the standard SF login page
Display a custom logout page
Display a custom single sign on page
How multi-factor authenticatoin can be configured?
can be configured for users by setting the ‘Session Security Level Required at Login‘
‘Multi-Factor Authentication‘ should be in the ‘High Assurance ‘ column on the ‘Session Settings‘ page in Setup
What happened when enabling Single Sign-on with delegated authentication for the org.
Which are the benefits of delegated authentication?
It makes the login page private and accessible only behind a corporate firewall
It can be configured to use a stronger form of user authentication, such as integration with a secure identity provider
What are the organizational-level security access controls?
Multi-factor authentification
password policies
trusted IP ranges
What is true when setting up users?
A. The profiles available depending on the license type selected
B. the username and email address can be different. except when setting up multiple users
Look through the login forensics to spot any suspicious attempts to gain access to the org.
What can login foresics provide?
The average number of logins per user per a specified time period
who logged in more than the average number of times
who logged in during non-business hours
When creating multiple users and using Data Loader, which information is necessary to create a user?
First name, Last name, Alias, username, email, role and user license
What can be controlled in Profiles?
Object permissions
Page Layouts
Field Level Security
ensuring that a record type is available to users
Controlling which Apex classes and Visualforce pages users can access
Making certain fields of an object read only for users
What do you know about Opportunity Teams and Opportunity Team Member object
Opportunity team members can be added by Salesforce Administrator, the opportunity owner, and users above the owner in the role hierarchy.
Opportunity team must be enabled in Setup
SF Admins or users can create default teams.
Custom fields can be added to the Opportunity Team Member object
In a private sharing model, will a manager be able to edit account records owned by a user below them in the role hierarchy?
Yes, access is granted by default to users in a higher role for standard objects
‘Grant access using hierarchies‘ is always checked for standard objects such as account and cannot be changed
What Folders can be used for?
-> to store
reports
dashboards
files
email templates
What can be included in a public group?
-> pubic group can contain a combination of users, roles, users assigned to specific territories, other public groups and roles, and subordinates in the hierarchy
Minimum Acces - Salesforce profile
-> is a least-privilege profile that includes:
Access Activities
Chatter Internal User
Lightning Console User
View Help Link permissions
Subfolders are used to organize reports and dashboards in Lightning Experience.
What are the features of subfolders?
organize reports and dashboards into a logical structure
folder sharing is at the root level, not subfolder level
subfolders can be created in user-created folders, but not in Public or Private folder
Difference between record-level sharing and object-level sharing?
Record-level sharing is related to:
organization-wide defaults
Roles
Object-level permissions are defined by:
Profiles and permission sets
‘Controlled by Parent‘ in the context of the Contact object
the access to the contact will be controlled by the access the user has to the parent, in this case, Account
Multi-Currency
must be enabled on the Company Information page by admin
the corporate currency must be defined
Currencies must be made active for them to be used
Reporting and Forecasting can be done in the record currency and corporate currency
cannot be disabled, once disabled
User can set their individual currency on the Personal Information page.
Multi-Currency:
Exchange rates and dated exchange rates
exchange rates: between active currencies can be set on the Manage Currencies Page
Dated exchange rates: this can be used by enabling Advanced Currency Management. It is used for tracking the exchange rates at the date oppotys close
What is determined by Business Hours?
determine the times when users are available ( when to escalate a Case) to support customers and are the basis for the computation of support process hours.
Multiple business hours can be defined, but only one can be used as a default
Standard Fiscal Year
Gregorian calendar
can be configured to start on the first day of any month
Fiscal Year Structure
cannot be retrieved back to standard structure - can be replicated b choosing a Gregorian calendar
Lightning Components
which components can be added
What makes LC dynamic?
standard, custom, and third-party components can be added to a Lightning page using the Lightning App Builder.
Visibility filters can be set for components on Lightning App and home pages to make them dynamic
Home Page
Once the home page has been saved, it needs to be activated to make it visible to the users.
can be assigned as the Org Default, App Default or assigned to an App and Profile combination.
When editing Home Page for the first time, SF makes a copy of the standard page. This copy can be then customized
Activity Section in the Lightning Usage App
Usage Section
Lightning App Builder
Activity Section: user activity data, such as daily active users, can be viewed separately for Lightning Experience and SF mobile app
Usage Section: browser usage and page performance data can be viewed separately for Lightning Exp and Sf mobily app
Lightning App Builder: shows where in the org the desktop record pages are slow
App Manager: the options
Form Factor
Personalization Settings
Utility Items
Assign App to User Profiles
Form Factor can be configured to support desktop, phone or both
Personalization Settings: Lightning App can be personalizes depending on the navigation style
Utility Items: are productivity tools that can be added to an app
Deployment options
Change Sets: can be used to migrate metadata
Ant Migration Tool: command line utility can be used to move metadata between a local directory and an Org
SF Extensions for Visual Studio
Salesforce CLI
Unmanaged Package: can be used to distribute open-source projects or application templates to any org
Which Setting allows the default record type to be selected and applied automatically for the user when creating a new record for the object
Reford type preference in personal settings
Scenario: users to see only the campaign members whose lead or contact records they can access in Salesforce.
modify the org-wide sharing default setting for the Campaign Member object
-> For this requirement, the org-wide sharing default setting for the Campaign Member object can be set to ‘Controlled by Campaign Member‘. This would ensure that users see only the campaign members whose lead, contact, account to person account records they have access to.
Sharing rules
can be added to grant access to users at the same level.
The sharing rule would be based on the record owner and share records owned by one role with users of another role.
Field- level Security
can be used to set whether a field is visible or read-only by Profile.
It also allows defining field accessibility in places other than the detail page, whether users should be able to access particular field via the detail page, reports, API ets.
Fields can be set as hidden in the page layout but users will still be able to access the fields in reports, search an list views
Profile Object Settings include:
Tab Settings
Record types and page layout settings
object permissions
field permissions
Sharing Settings available on Pricebook object
Use - any user can view and add the Pricebook to Oppty
View only
No access - users cannot see Price Books or add them to Opptys unless sharing rules are used to give visibility
What do users need when they want to access files in a library?
if at a later date
users need to be members of the library (either as an individual users or part of a public group)
if the users need to have access to a later date, the file can be added to the library, and then the sales public group can be added as members with the appropriate access type at a later date
Session-based access control:
with session-based access control, access can be given to users for a specific session. Once the session expires, the access is revoked automatically without having to remove the assignments
can be used with permission set groups that contain multiple permission sets.
Creating a new tab and assigning to an app has 3 steps:
Create, name the tab and select the object
Choose the user profiles for which the tab will be available
Choose the apps for which the custom tab will be available
List Email
allows personalized individual emails to be sent to multiple contacts, leads, or campaign members. Email templates with merge fields can be used to customize each of these emails
alternative in SF Classic: Mass Email
Last changed2 years ago